VDB
CVE-2024-9861
CVE-2024-9861
PUBLISHED
CVSS 8.100000381469727 HIGH
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. This is due to missing validation on the token being supplied during the otp login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they know the phone number associated with that user.
EPSS 0.63% · 48.6th percentile
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.63%
48.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| miniorange | otp_verification_with_firebase | 0 |
| cyberlord92 | Miniorange OTP Verification with Firebase | * |
Timeline
- Oct 17, 2024 EPSS Score
- Oct 17, 2024 Coalition ESS Score
- Oct 17, 2024 CVE Published
- Oct 18, 2024 Coalition ESS Score
- Nov 5, 2024 EPSS Score
- Nov 24, 2024 EPSS Score
- Dec 21, 2024 Coalition ESS Score
- Jan 2, 2025 EPSS Score
- Jan 21, 2025 EPSS Score
- Jan 28, 2025 Coalition ESS Score
- Feb 9, 2025 EPSS Score
- Feb 28, 2025 EPSS Score
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/04045ec3-dd8e-4ac5-bd73-eef6205ecc62?source=cve url
- https://plugins.trac.wordpress.org/browser/miniorange-firebase-sms-otp-verification/tags/3.6.0/handler/forms/class-loginform.php#L144 url
- https://plugins.trac.wordpress.org/browser/miniorange-firebase-sms-otp-verification/tags/3.6.0/handler/forms/class-loginform.php#L190 url
- https://plugins.trac.wordpress.org/changeset/3169869/miniorange-firebase-sms-otp-verification#file3 url
- https://nvd.nist.gov/vuln/detail/CVE-2024-9861 advisory